Guides

Networking & NAT

Address management, NAT and port-forwarding for private guests, plus a read-only firewall view.

IP zones (IPAM)

Define IP zones (subnets with a gateway and nameservers) under Settings, and NexoVirt manages address allocation for you. When creating a guest you can pick DHCP or allocate the next free address from a zone, which is injected as a static configuration.

Zones show a live allocation table; reinstalling a guest keeps its IP, deleting it releases the address, and you can change or release an IP from the guest's Network tab. NexoVirt can also scan a host's bridges to pre-fill new zones and reconcile addresses already in use.

NAT & port-forwarding

For guests on a private bridge, the per-host NAT page lets them reach the internet through the host's WAN interface (MASQUERADE) and lets you expose them with port-forwards: mapping a public port on the WAN interface to a private guest's port. The WAN interface and private subnet are pre-filled from NexoVirt's network detection. You manage port-forwards in a table and apply the rules with one click (behind a confirmation).

Read-only firewall view

The Networking page has an Analyze button that reads the host's current firewall: iptables, nftables, ufw, firewalld and pve-firewall, and shows you which stack is active and its current rules, plus a NAT map, so you can spot conflicts before changing anything. This is strictly read-only. The latest analysis is stored and shown with an “as of” marker so the page loads instantly.

Network map

A read-only host network topology shows the host's classified bridges (WAN / private / internal), the guests on each (matched by IP), and a NAT / port-forward overlay: a quick visual of how traffic flows on a host.

This documentation describes NexoVirt as it stands today and grows with it. Something missing? Get started free.
On this page